Skip to main content
Glossary

Compliance terms, in plain English

The words that turn up in an audit request, a customer security questionnaire or a regulator letter — what each one means, and what it actually asks of you.

UK law, stated as UK law
The limit named, not just the term
Free to read, no account

Browsing all 20 terms. Search by name, code or plain-English purpose.

Data protection

DSAR (data subject access request)
A request from an individual to see the personal data an organisation holds about them, together with information about how and why it is being used. Under UK GDPR the response is due within one calendar month of receipt.
One calendar month, not 30 days — the distinction matters for requests received in a 31-day month. The deadline can be extended by a further two months for complex or numerous requests, but the individual must be told within the first month.
Policy library
Personal data
Any information relating to an identified or identifiable living person. That includes obvious identifiers like a name or email, and anything that singles someone out when combined with other data an organisation holds.
The bar is lower than most people assume. An IP address, a staff number, or a CCTV image can all be personal data.
Special category data
The UK GDPR classes of data needing extra protection: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to identify someone, health data, and data about sex life or sexual orientation.
Processing it needs both a lawful basis and a separate Article 9 condition. Criminal offence data is not special category data but has its own rules under Article 10.
Personal data breach
A security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. If it is likely to risk people’s rights and freedoms it must be reported to the ICO within 72 hours of becoming aware of it.
Losing access to data counts, not just leaking it. A ransomware attack that encrypts records you cannot restore is a breach even if nothing left the building.
DPIA (data protection impact assessment)
An assessment of the privacy risk in a new project or system, required under UK GDPR where processing is likely to result in a high risk to individuals — for example large-scale profiling, systematic monitoring, or processing special category data at scale.
It has to be done before the processing starts. A DPIA written after launch is a record, not a safeguard.
ROPA (record of processing activities)
A written inventory of what personal data an organisation processes, why, who it is shared with, where it goes and how long it is kept. Required under Article 30 of the UK GDPR.
The under-250-employee exemption is narrower than it looks: it falls away if the processing is not occasional, is likely to risk people’s rights, or involves special category data — which covers most employers.
Processor and controller
The controller decides why and how personal data is processed. A processor acts on the controller’s instructions. Which one you are determines your obligations, and it is a question of fact rather than what a contract calls you.
Article 28 requires a written contract between them covering specified terms. Using a supplier without one is itself a compliance gap.
Sub-processors
Retention schedule
A documented list of what records an organisation keeps, for how long, and when the clock starts. It is how the storage-limitation principle becomes something a person can actually follow.
The common failure is not the schedule but the copies: backups, mailboxes and third-party systems that nothing sweeps.
Right to erasure
An individual’s right to have personal data about them deleted in defined circumstances, such as when it is no longer needed for the purpose it was collected for.
It is not absolute. Data needed to meet a legal obligation, or to establish or defend a legal claim, can be retained — and in practice erasure is often implemented as pseudonymisation, because records that others rely on cannot simply vanish.

Security

ISO/IEC 27001
The international standard for an information security management system — a documented, risk-led programme for managing information security, rather than a fixed checklist of technical measures.
Certification is awarded by an accredited body after an audit. Having policies mapped to ISO 27001 is a precondition for certification, not the same thing as holding it.
Standards directory
SOC 2
A US-originated assurance report on a service organisation’s controls, produced by an independent auditor against the Trust Services Criteria. A Type I report covers design at a point in time; a Type II covers operating effectiveness over a period.
SOC 2 is a report, not a certificate. There is no such thing as being "SOC 2 certified", though almost everyone says it.
Standards directory
Cyber Essentials
A UK government-backed scheme covering five technical control areas: firewalls, secure configuration, security update management, user access control, and malware protection. Certification is self-assessed; Cyber Essentials Plus adds independent technical verification.
It is a requirement for many UK public-sector contracts, which is usually why an organisation first encounters it.
Standards directory

Governance

Policy
A written statement of how an organisation does something, who is accountable for it, and what people are expected to do. It is the documented intent, approved by someone with the authority to approve it.
A policy is not a control. The policy says access is reviewed quarterly; the control is the review actually happening, and the evidence is the record that it did. Auditors ask for all three and most organisations only have the first.
Policy library
Control
A specific thing an organisation does to reduce a risk — enforcing multi-factor authentication, reviewing access quarterly, requiring two approvers above a spend threshold.
Controls are what a standard actually tests. A control that exists on paper but is not operating is a finding, not a pass.
Controls explorer
Risk assessment
A structured judgement about what could go wrong, how likely it is, how bad it would be, and what is being done about it. The output is a recorded decision, not a score.
In UK health and safety law a written risk assessment is a legal duty for employers with five or more employees, under the Management of Health and Safety at Work Regulations 1999.

Employment

Protected disclosure (whistleblowing)
A disclosure by a worker about specified kinds of wrongdoing that attracts legal protection from dismissal or detriment under the Employment Rights Act 1996.
Protection turns on the worker reasonably believing the disclosure is in the public interest. Good faith has not been the test since the Enterprise and Regulatory Reform Act 2013 — it now only affects compensation.
Acas Code of Practice
The statutory code setting out the minimum fair process for disciplinary and grievance cases in Great Britain. An employment tribunal can adjust compensation by up to 25% where an employer unreasonably fails to follow it.
Competent person
The person an employer appoints to help meet health and safety duties, required by Regulation 7 of the Management of Health and Safety at Work Regulations 1999. Competence means the right skills, knowledge and experience — not a specific qualification.

Product

Guided preview
Quick Policy’s free tier. You complete an onboarding profile about how your business actually operates, and the platform drafts your core policies from those answers so you can read them in full before deciding anything. No card is required.
What the preview does not include is publishing, PDF export, and sending policies to your team for sign-off. Those unlock on a paid plan.
PricingPlatform overview
Standards scorecard
Quick Policy’s view of how a generated policy measures against the standards you selected, with the gaps named in plain English.
It is a documentation gap view, not certification and not evidence that a control is operating. A green score means the policy says the right things, which is the first step and not the last one.
Standards directory

These definitions are written to be useful, not to be relied on as legal advice. Where a duty differs between England and Wales, Scotland and Northern Ireland, check which applies to you — several of the statutes referenced here do not extend across the whole UK.

See these applied to your own business

Answer a few questions about how you operate and Quick Policy drafts your core policies against the standards you select. No card required.